Description
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.8 | Impact: 2.5Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
2GHSAGHSA-gw5c-576j-pf63: A insertion of sensitive information into log file in Fortinet FortiDLP 12↗2025-10-16 ▶ CVEListCVE-2025-46752: A insertion of sensitive information into log file in Fortinet FortiDLP 12↗2025-10-16 ▶ 📋Vendor Advisories
2FortinetA insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al...↗2025-10-16 ▶ MicrosoftAn issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data leading to a crash.↗2023-10-10 ▶